Cyber Incident Victim: Phetchabun Hospital
Date:
Sep 2021
Location:
Thailand
Summary
A hacker stole personal data of over 10,000 patients from a Thai hospital, with officials initially downplaying the incident by claiming the compromised information was "not important." Social media reports had alleged a larger breach involving 16 million patients' records being offered for sale, though the hospital disputed this scale. Subsequent revelations confirmed health-related information was included in the stolen data, contradicting authorities' earlier minimization of the breach's severity.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around September 7, 2021, Phetchabun Hospital in Thailand experienced a data breach involving the theft of personal details belonging to more than 10,000 patients. Initial reports circulated on social media claimed a significantly larger compromise, alleging that data from 16 million patients under Thailand’s Public Health Ministry had been hacked and offered for sale. These claims prompted a public response from Phetchabun Governor Krit Kongmuang, who sought to address the allegations while minimizing their severity. Hospital and government officials explicitly downplayed the incident, characterizing the stolen patient information as “not important” in public statements. The breach disclosure followed a pattern where authorities initially contested the scale and sensitivity of the exposed data.

Subsequent revelations confirmed that health information was included in the compromised data set, contradicting early official assertions about the data’s lack of significance. The incident drew attention to the risks of downplaying cybersecurity breaches, as the hospital’s initial response was followed by acknowledgments of broader data exposure. While the exact attack vector and intrusion timeline were not detailed in available reports, the breach impacted at least 10,000 individuals’ personal and medical records. Public statements focused on reputational damage control rather than technical remediation steps, containment measures, or forensic findings. The discrepancy between social media reports of 16 million affected patients and the confirmed 10,000 cases from Phetchabun Hospital created public confusion about the incident’s scope. No additional information was provided regarding data recovery, ransom demands, or law enforcement involvement in the breach response.
